Description
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2145-1 | twisted security update |
Debian DLA |
DLA-2145-2 | twisted security update |
Debian DLA |
DLA-2927-1 | twisted security update |
EUVD |
EUVD-2020-0228 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request. |
Github GHSA |
GHSA-h96w-mmrf-2h6v | Improper Input Validation in Twisted |
Ubuntu USN |
USN-4308-1 | Twisted vulnerabilities |
Ubuntu USN |
USN-4308-2 | Twisted vulnerabilities |
References
History
Mon, 25 Nov 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Twisted
Twisted twisted |
|
| CPEs | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Twistedmatrix
Twistedmatrix twisted |
Twisted
Twisted twisted |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:50:57.819Z
Reserved: 2020-03-05T00:00:00.000Z
Link: CVE-2020-10108
No data.
Status : Modified
Published: 2020-03-12T13:15:12.293
Modified: 2024-11-25T18:12:24.673
Link: CVE-2020-10108
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN